VDB
Sign up
MEDIUM6.1

GHSA-4c5w-qqfg-grf3

Symphony CMS XSS Vulnerabilities

Quick fix

GHSA-4c5w-qqfg-grf3 — symphonycms/symphony-2: upgrade to the fixed version with the command below.

composer require symphonycms/symphony-2:^2.6.4

Details

Multiple cross-site scripting (XSS) vulnerabilities in `content/content.systempreferences.php` in Symphony CMS before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1) `email_sendmail[from_name]`, (2) `email_sendmail[from_address]`, (3) `email_smtp[from_name]`, (4) `email_smtp[from_address]`, (5) `email_smtp[host]`, (6) `email_smtp[port]`, (7) `jit_image_manipulation[trusted_external_sites]`, or (8) `maintenance_mode[ip_whitelist]` parameters to system/preferences.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symphonycms/symphony-2
Introduced in: 0Fixed in: 2.6.4
Fixcomposer require symphonycms/symphony-2:^2.6.4

References